Anatomy of the SolarWinds Hack: Who What Where When How
The a16z Show1 Feb 2021

Anatomy of the SolarWinds Hack: Who What Where When How

In this special “3x”-long episode of our (otherwise shortform) news analysis show 16 Minutes -- past such 2-3X explainer episodes have covered section 230, Tiktok, GPT-3, the opioid crisis, more -- we cover the SolarWinds hack, one of the largest (if not the largest!) publicly known hacks of all time... and the ripple effects are only now starting to be revealed. Just this week, the U.S. Cybersecurity and Infrastructure Security Agency shared (as reported in the Wall Street Journal) that approximately 30% of both private-sector and government victims linked to the hack had no direct connection to SolarWinds. So who was compromised, do they even know, can they even know?!

Because this hack is a supply-chain compromise involving various third-party software and services all connected together in a "chain of chains", the knock-on effects of it will be revealed (or not!) for years to come. So what do companies -- whether large enterprise, mid-sized startup, or small business -- do? What actually happened, and when does the timeline really begin? While first publicly revealed in December 2020 -- we first covered the news in episode #49 here when it first broke, and there have been countless headlines since (about early known government agency victims, company investigations, other tool investigations, debates over who and how and so on) -- the hack actually began not just a few months but years earlier, involving early tests, legit domains, and a very long game.

We help cut through the headline fatigue of it all, tease apart what's hype/ what's real, and do an "anatomy of a hack" step-by-step teardown -- the who, what, where, when, how; from the chess moves to technical details -- in an in-depth yet accessible way with Sonal Chokshi in conversation with a16z expert and former CSO Joel de la Garza and outside expert Steven Adair, founder and president of Volexity. The information security firm (which specializes in incident response, digital forensics/ memory analysis, network monitoring, and more) not only posted guidance for responding to such attacks, but also an analysis based on working three separate incidents involving the SolarWinds hackers. But how did they know it was the same group? And why was it not quite the perfect crime?

image: Heliophysics Systems Observatory spacecraft characterize, in the highest cadence, the constant stream of particles exploding from the sun affect Earth, the planets, and beyond via NASA Goddard Space Flight Center / Flickr

Stay Updated:

Find a16z on YouTube: YouTube

Find a16z on X

Find a16z on LinkedIn

Listen to the a16z Show on Spotify

Listen to the a16z Show on Apple Podcasts

Follow our host: https://twitter.com/eriktorenberg

Please note that the content here is for informational purposes only; should NOT be taken as legal, business, tax, or investment advice or be used to evaluate any investment or security; and is not directed at any investors or potential investors in any a16z fund. a16z and its affiliates may maintain investments in the companies discussed. For more details please see a16z.com/disclosures.


Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Episoder(1000)

a16z Podcast: On Government as Software Builder, Not Just Buyer

a16z Podcast: On Government as Software Builder, Not Just Buyer

We already know that the government is one of the largest IT buyers, but in many ways it is also an IT builder. Especially for areas where the government is doing something that no one else is doing, ...

14 Jul 201623min

a16z Podcast: Software Programs the World

a16z Podcast: Software Programs the World

"All of a sudden you can program the world" -- it's the continuation of the software eating the world thesis we put out over five years ago, and of the trajectory of past and current technology shifts...

11 Jul 201640min

a16z Podcast: Beyond One Size Fits All for Startup Employee Options

a16z Podcast: Beyond One Size Fits All for Startup Employee Options

Do we need a new pay system for the way startup employees are compensated? While many people agree that the current 90-day exercise practice — an outdated relic of when companies used to go public/get...

1 Jul 201632min

a16z Podcast: When Humanity Meets A.I.

a16z Podcast: When Humanity Meets A.I.

with Fei-Fei Li (@drfeifei), Frank Chen (@withfries2), and Sonal Chokshi (@smc90) Who has the advantage in artificial intelligence — big companies, startups, or academia? Perhaps all three, especially...

28 Jun 201638min

a16z Podcast: Fintech Revolution or Evolution?

a16z Podcast: Fintech Revolution or Evolution?

How far along are we towards the vision of a "cashless, cardless, walletless, frictionless future" for fintech? We're not quite there yet, argued BuzzFeed News technology reporter Charlie Warzel in a ...

22 Jun 201645min

a16z Podcast: An Economics Take on the Sharing Economy

a16z Podcast: An Economics Take on the Sharing Economy

Love the term or hate it, the concept and reality of the "sharing economy" (or "gig economy" and so on) is here to stay. And in fact, argues NYU Stern professor and researcher Arun Sundararajan, it ma...

16 Jun 201628min

a16z Podcast: Apple and the Widgetification of Everything

a16z Podcast: Apple and the Widgetification of Everything

The world's most valuable company, Apple, made a number of seemingly incremental announcements at its most recent annual developer's conference (WWDC) -- that Apple Pay is coming to the web; that Siri...

14 Jun 201625min

a16z Podcast: Move Fast But Don't Break Things (When It Comes to Computational Biology)

a16z Podcast: Move Fast But Don't Break Things (When It Comes to Computational Biology)

The mindset of "move fast and break things", while great for code, isn't exactly great for the human body. So adding computation to biology -- especially in the slow-moving pharmaceutical industry, wh...

14 Jun 201629min

Populært innen Business og økonomi

stopp-verden
lydartikler-fra-aftenposten
dine-penger-pengeradet
e24-podden
rss-penger-polser-og-politikk
rss-borsmorgen-okonominyhetene
finansredaksjonen
pengesnakk
pengepodden-2
tid-er-penger-en-podcast-med-peter-warren
rss-sunn-okonomi
utbytte
morgenkaffen-med-finansavisen
livet-pa-veien-med-jan-erik-larssen
stormkast-med-valebrokk-stordalen
rss-markedspuls-2
lederpodden
liberal-halvtime
rss-politisk-preik
okonomiamatorene